Six instruments are changing how grid-scale storage is bought, financed and operated. Two are already in force. Three take effect in 2027. One is a proposal.
We set them out with their citations and their dates. We draw no conclusions from them. What matters to a project depends on how it is financed, who is buying and where it connects, and those are your circumstances, not ours.
2Already in force
3Take effect in 2027
1A proposal, not adopted
Solid marks are in force. Outlined marks are scheduled. Financing dates are as reported; the guidelines have not been published.
01
Financing
In effect since May 2026, as reported
December 2025. The European Commission’s Joint Communication on strengthening EU economic security names solar inverters as an example of a critical-infrastructure dependency, citing reliance on a single supplier, and the cyber risk of manipulating electricity production, preventing production, and gaining access to operational data. It states that the Commission will prevent access by high-risk entities to Union-supported actions, including those supported by public financial institutions and instruments.[1]
May 2026. The Commission communicated guidelines to financial institutions restricting EU-backed funding for projects using inverters from designated high-risk suppliers, including entities ultimately owned or controlled from those jurisdictions. They are applied through project-level checks and the EU Financial Regulation.[2]
Affected funding includes European Investment Bank lending, EU programmes, development finance institutions, and commercial facilities relying on EU-backed funds, guarantees or blended finance.
Reported dates: the process began on 1 May 2026. Grandfathering exemptions had to be notified by 1 September 2026, with final approvals by 1 November 2026. Reporting indicates further tightening from April 2027, with accounts differing on precisely what that date governs.
The test is ownership and control, not manufacturing location.
The guidelines themselves have not been published. The December 2025 Communication is the published policy behind them. Reporting based on Commission documents states that energy storage power conversion systems are explicitly included; that extension has not been published.[3]
02
Procurement and auctions
In force since 30 December 2025
Under Article 26 of the Net-Zero Industry Act, Member States must apply non-price criteria to at least 30% of the volume auctioned per year in renewable energy auctions, or alternatively at least 6 GW per year.
In those auctions, responsible business conduct, cybersecurity and data security, and ability to deliver the project are pre-qualification criteria. The contribution to sustainability and resilience is assessed as either a pre-qualification or an award criterion. Where used as award criteria, each carries a minimum weight of 5%, with a combined weight of between 15% and 30%.
Public procurement of net-zero technologies is covered separately, under Article 25, with its own sustainability and resilience requirements. Contracting entities include transmission and distribution system operators.
Battery and energy storage is a listed net-zero technology.[4] [5] [6]
03
Cybersecurity in operation
Entity notification by mid-September 2027
The Network Code on Cybersecurity applies to entities designated as high-impact or critical-impact: transmission and distribution system operators, nominated electricity market operators, market platforms, and balancing service providers. Designation uses the Electricity Cybersecurity Impact Index.
Designated operators must verify that critical information and communications technology components meet cybersecurity specifications, through EU certification schemes or internal assurance. Supply-chain controls require secure-by-design development. Suppliers are required to provide technical assurances and certifications on request.
First risk report twelve months after notification. Compliance demonstration twenty-four months after controls are adopted.[7]
04
Product cybersecurity
Main obligations from December 2027
The Cyber Resilience Act introduces lifecycle cybersecurity requirements for connected hardware and software: secure development, vulnerability management, security updates and incident reporting.
05
The battery passport
Mandatory from 18 February 2027
Every industrial battery over 2 kWh placed on the EU market must carry a digital battery passport: unique identifier, key technical characteristics, carbon footprint, and documentation of electrochemical performance and durability. Accessible by QR code, with differentiated access for the public, regulators and end-of-life processors.
The Commission’s guidance of 21 August 2026 sets out 71 data points and marks which are required from February 2027. State of health and internal resistance are not among them at that date; the guidance indicates they may be added by a later delegated act.[8]
06
Proposed
Proposed 4 March 2026 · not adopted
The Industrial Accelerator Act would introduce Union-origin requirements in public procurement, applying to procedures launched on or after 1 January 2029. Battery energy storage systems are among the technologies named. Union origin is defined to include customs-union, free-trade-agreement and WTO Government Procurement Agreement partners.
It is a proposal in the ordinary legislative procedure. Nothing in it applies today.[9]
Diligence
What a buyer now has to be able to answer
These questions support project due diligence. What applies depends on the operator, the equipment, and the procurement and financing arrangements.
Question
Bessify
Who owns the firmware in the power conversion system and the battery management system?
Bessify. Developed in Estonia. There is no third-party control layer.
How does the system receive dispatch?
Setpoints arrive from the owner’s optimiser, energy management system or site controller. This is normal operation.
What can be changed from outside the site?
Nothing in Core. Protection limits and Core firmware are set locally, by physical access, and recorded.
What is configurable by the owner?
Monitoring, interfaces and update handling. Delivered closed; the owner can open them and owns that decision.
Is firmware updated over the air?
Not as delivered. Updates are applied on the local network at the site, or unit by unit, and recorded. Over-the-air updating is available at the owner’s request.
What does the system do if the connection is lost?
It continues within its limits. Safety and control do not depend on a connection.
Does the owner get their data?
All measurement and event data is recorded locally and is available to the owner in full. Data leaving the system does not create a path into it.
Where is operational data processed?
Locally, on the edge computer in the Power Compartment.
Status
Where Bessify stands
Power conversion system
Designed, manufactured and controlled by Bessify in Estonia
Firmware
Developed and owned by Bessify
Cell record
Begins with the manufacturer’s data; continues through re-scan, voltage measurement after shipping, a recorded resistance baseline, and final position by floor, row and place in the row
Inverter grid-code certification
Begins September 2026, scheduled Q1 2027
System certification
Follows inverter certification, scheduled Q3 2027
Battery passport
Cell record in place. Passport service and carbon footprint declaration in scope for 2027.
Cyber Resilience Act
Reporting obligations apply from 11 September 2026. Main obligations apply from 11 December 2027.